🛡️ مركز معلومات الثغرات
قاعدة بيانات الثغرات والتهديدات الأمنية المحدّثة
| المعرّف | الخطورة | CVSS | الوصف | الحالة | النشر |
|---|---|---|---|---|---|
| CVE-2021-47961 | مرتفع | 8.1 |
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to …
|
— | أبريل 10, 2026 |
| CVE-2026-35641 | مرتفع | 7.8 |
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that …
|
⚡ Exploit | أبريل 10, 2026 |
| CVE-2026-35668 | مرتفع | 7.7 |
OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to re…
|
⚡ Exploit | أبريل 10, 2026 |
| CVE-2026-3360 | مرتفع | 7.5 |
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Ref…
|
— | أبريل 10, 2026 |
| CVE-2026-40073 | مرتفع | 7.5 |
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under…
|
✅ Patch | أبريل 10, 2026 |
| CVE-2026-40074 | مرتفع | 7.5 |
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redir…
|
✅ Patch | أبريل 10, 2026 |
| CVE-2026-35650 | مرتفع | 7.5 |
OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa…
|
✅ Patch | أبريل 10, 2026 |
| CVE-2026-6031 | مرتفع | 7.3 |
A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the …
|
— | أبريل 10, 2026 |
| CVE-2026-6036 | مرتفع | 7.3 |
A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown fu…
|
— | أبريل 10, 2026 |
| CVE-2026-6037 | مرتفع | 7.3 |
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function…
|
— | أبريل 10, 2026 |
| CVE-2026-6004 | مرتفع | 7.3 |
A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the fil…
|
— | أبريل 10, 2026 |
| CVE-2026-6024 | مرتفع | 7.3 |
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfu…
|
— | أبريل 10, 2026 |
| CVE-2026-6038 | مرتفع | 7.3 |
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function…
|
— | أبريل 10, 2026 |
| CVE-2026-29002 | مرتفع | 7.2 |
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin …
|
⚡ Exploit | أبريل 10, 2026 |
| CVE-2026-4162 | مرتفع | 7.1 |
The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th…
|
— | أبريل 10, 2026 |
| CVE-2026-33704 | مرتفع | 7.1 |
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arb…
|
✅ Patch | أبريل 10, 2026 |
| CVE-2026-5815 | مرتفع | 8.8 |
A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-…
|
— | أبريل 9, 2026 |
| CVE-2026-5980 | مرتفع | 8.8 |
A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /g…
|
— | أبريل 9, 2026 |
| CVE-2026-4326 | مرتفع | 8.8 |
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and in…
|
— | أبريل 9, 2026 |
| CVE-2026-5979 | مرتفع | 8.8 |
A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ …
|
— | أبريل 9, 2026 |